# self-hosted

Published articles for self-hosted.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## How libreboot.org is hosted

DevFeed: [How libreboot.org is hosted](<https://devfeed.tech/articles/how-libreboot-org-is-hosted-32671.md>)

Original publisher: [Read original article](<https://libreboot.org/news/fedfree.html>)

Author: Leah Rowe

Published: 2026-09-17T04:32:50.666044Z

Content type: article

Language: en

Sources: [News about Libreboot releases and development](<https://devfeed.tech/sources/news-about-libreboot-releases-and-development.md>)

Topics: [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>), [hosting](<https://devfeed.tech/topics/hosting.md>), [Internet](<https://devfeed.tech/topics/internet.md>), [static-site-generator](<https://devfeed.tech/topics/static-site-generator.md>), [Git](<https://devfeed.tech/topics/git.md>), [forgejo](<https://devfeed.tech/topics/forgejo.md>)

Tags: [article](<https://devfeed.tech/tags/article.md>), [bios](<https://devfeed.tech/tags/bios.md>), [canoeboot](<https://devfeed.tech/tags/canoeboot.md>), [coreboot](<https://devfeed.tech/tags/coreboot.md>), [free-software](<https://devfeed.tech/tags/free-software.md>), [github](<https://devfeed.tech/tags/github.md>), [hosting](<https://devfeed.tech/tags/hosting.md>), [internet](<https://devfeed.tech/tags/internet.md>), [libre](<https://devfeed.tech/tags/libre.md>), [libreboot](<https://devfeed.tech/tags/libreboot.md>), [opensource](<https://devfeed.tech/tags/opensource.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [static-site-generator](<https://devfeed.tech/tags/static-site-generator.md>), [uefi](<https://devfeed.tech/tags/uefi.md>)

### AI overview

The article introduces the Federation of Freedom, or Fedfree, a website launched in December 2022 to teach people how to self-host internet servers using libre software. It documents the hosting setup used by libreboot.org and plans to add guides for mail, rsync, cgit, and Forgejo. The project aims to help people avoid defaulting to proprietary hosting services.

### Source excerpt

Article: How libreboot.org is hosted Web link: https://libreboot.org/news/fedfree.html

## Nextcloud Hub 26 Summer Released, Euro-Office Desktop App Coming Soon

DevFeed: [Nextcloud Hub 26 Summer Released, Euro-Office Desktop App Coming Soon](<https://devfeed.tech/articles/nextcloud-hub-26-summer-released-euro-office-desktop-app-coming-soon-31458.md>)

Original publisher: [Read original article](<https://selfhostlab.io/nextcloud-hub-26-summer-release/>)

Author: Christian Rakoot

Published: 2026-09-16T18:32:34Z

Content type: release

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [Nextcloud](<https://devfeed.tech/topics/nextcloud.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>), [microsoft 365](<https://devfeed.tech/topics/microsoft-365.md>)

Tags: [collaboration](<https://devfeed.tech/tags/collaboration.md>), [desktop](<https://devfeed.tech/tags/desktop.md>), [feature](<https://devfeed.tech/tags/feature.md>), [microsoft-365](<https://devfeed.tech/tags/microsoft-365.md>), [news](<https://devfeed.tech/tags/news.md>), [office](<https://devfeed.tech/tags/office.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [release](<https://devfeed.tech/tags/release.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>)

### AI overview

Nextcloud Hub 26 Summer is live, with the Euro-Office desktop app announced for release in the coming weeks. The update also includes faster browser-based Office features and partner-contributed tools for teams, calendar resource booking, and Tables.

### Source excerpt

Nextcloud's Hub 26 Summer is live today, headlined by a new Euro-Office desktop app arriving in the coming weeks, plus features co-built with partners including IONOS, SURF, and the German state of Schleswig-Holstein.

## n8n Patches 16 Security Vulnerabilities, 12 Rated High Severity

DevFeed: [n8n Patches 16 Security Vulnerabilities, 12 Rated High Severity](<https://devfeed.tech/articles/n8n-patches-16-security-vulnerabilities-12-rated-high-severity-31457.md>)

Original publisher: [Read original article](<https://selfhostlab.io/n8n-16-security-vulnerabilities-patched/>)

Author: Christian Rakoot

Published: 2026-09-16T18:31:20Z

Content type: news

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [n8n](<https://devfeed.tech/topics/n8n.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [patches](<https://devfeed.tech/topics/patches.md>), [Security](<https://devfeed.tech/topics/security.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>)

Tags: [automation](<https://devfeed.tech/tags/automation.md>), [n8n](<https://devfeed.tech/tags/n8n.md>), [news](<https://devfeed.tech/tags/news.md>), [patches](<https://devfeed.tech/tags/patches.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

n8n published a bi-weekly security update disclosing 16 fixed advisories: 12 rated High severity and 4 rated Medium. The article highlights an unauthenticated NoSQL injection in the MongoDB Chat Memory node that can disclose chat history across sessions, along with five High-severity credential-handling advisories.

### Source excerpt

n8n, the self-hosted workflow automation platform covered regularly on this site, published its bi-weekly security update on September 16, 2026. The bulletin, posted on the official n8n Community forum by a member of the n8n security team, discloses 16 advisories fixed since the previous update on September 2: 12 rated High severity and 4 rated [...]

## Running a Self-Hosted Tailscale Control Server Behind a Reverse Proxy

DevFeed: [Running a Self-Hosted Tailscale Control Server Behind a Reverse Proxy](<https://devfeed.tech/articles/running-a-self-hosted-tailscale-control-server-behind-a-reverse-proxy-34104.md>)

Original publisher: [Read original article](<https://philipptheserver.com/posts/headscale-behind-traefik-no-h2/>)

Author: Philipp Lehmann (philipp.lehmann@gruppe.ai)

Published: 2026-09-15T07:00:00Z

Content type: tutorial

Language: en

Sources: [Philipp Lehmann](<https://devfeed.tech/sources/philipp-lehmann.md>)

Topics: [tailscale](<https://devfeed.tech/topics/tailscale.md>), [proxy](<https://devfeed.tech/topics/proxy.md>), [traefik](<https://devfeed.tech/topics/traefik.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [TLS handshake](<https://devfeed.tech/topics/tls-handshake.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>), [Homelab](<https://devfeed.tech/topics/homelab.md>)

Tags: [dns](<https://devfeed.tech/tags/dns.md>), [docker](<https://devfeed.tech/tags/docker.md>), [h2](<https://devfeed.tech/tags/h2.md>), [homelab](<https://devfeed.tech/tags/homelab.md>), [networking](<https://devfeed.tech/tags/networking.md>), [proxy](<https://devfeed.tech/tags/proxy.md>), [reverse-proxy](<https://devfeed.tech/tags/reverse-proxy.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [tailscale](<https://devfeed.tech/tags/tailscale.md>), [tls](<https://devfeed.tech/tags/tls.md>), [tls-handshake](<https://devfeed.tech/tags/tls-handshake.md>), [traefik](<https://devfeed.tech/tags/traefik.md>)

### AI overview

This tutorial explains how to run a self-hosted Tailscale control server, Headscale, behind Traefik. It finds that the reverse proxy must use TLS with HTTP/1.1 only because Tailscale's noise handshake expects a full-duplex byte stream and can fail when ALPN negotiates HTTP/2.

### Source excerpt

Headscale behind Traefik: tls.options=no-h2@file with alpnProtocols http/1.1, because the Tailscale noise handshake breaks when ALPN negotiates h2.

## Appwrite Init 2026 recap: Everything we shipped

DevFeed: [Appwrite Init 2026 recap: Everything we shipped](<https://devfeed.tech/articles/appwrite-init-2026-recap-everything-we-shipped-26795.md>)

Original publisher: [Read original article](<https://appwrite.io/blog/post/appwrite-init-2026-recap>)

Author: Aishwari Pahwa

Published: 2026-09-15T00:00:00Z

Content type: release

Language: en

Sources: [Appwrite Blog](<https://devfeed.tech/sources/appwrite-blog.md>)

Topics: [Appwrite](<https://devfeed.tech/topics/appwrite.md>), [releases](<https://devfeed.tech/topics/releases.md>), [PostgreSQL](<https://devfeed.tech/topics/postgresql.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>), [Firewall](<https://devfeed.tech/topics/firewall.md>), [OAuth 2.0](<https://devfeed.tech/topics/oauth2.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>)

Tags: [2](<https://devfeed.tech/tags/2.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [init](<https://devfeed.tech/tags/init.md>), [oauth2](<https://devfeed.tech/tags/oauth2.md>), [postgresql](<https://devfeed.tech/tags/postgresql.md>), [recap](<https://devfeed.tech/tags/recap.md>), [release](<https://devfeed.tech/tags/release.md>), [releases](<https://devfeed.tech/tags/releases.md>), [s3](<https://devfeed.tech/tags/s3.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>)

### AI overview

An Appwrite Init 2026 recap covering five days of launches, including Appwrite 2.0, a redesigned Console, native PostgreSQL, VectorsDB, DocumentsDB, MySQL, S3-compatible Storage, Firewall, OAuth2, and Domains.

### Source excerpt

An Appwrite Init 2026 recap of all five days of launches, from Appwrite 2.0 and native PostgreSQL to VectorsDB, S3 support, Firewall, OAuth2, and Domains.

## Seven Reliability Tests for Home Lab Services

DevFeed: [Seven Reliability Tests for Home Lab Services](<https://devfeed.tech/articles/i-don-t-trust-a-home-lab-service-until-it-passes-these-7-tests-10489.md>)

Original publisher: [Read original article](<https://www.virtualizationhowto.com/2026/09/i-dont-trust-a-home-lab-service-until-it-passes-these-7-tests/>)

Author: Brandon Lee

Published: 2026-09-13T12:34:15Z

Content type: tutorial

Language: en

Sources: [Virtualization Howto](<https://devfeed.tech/sources/virtualization-howto.md>)

Topics: [Homelab](<https://devfeed.tech/topics/homelab.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Network](<https://devfeed.tech/topics/network.md>), [Proxmox](<https://devfeed.tech/topics/proxmox.md>)

Tags: [home-lab](<https://devfeed.tech/tags/home-lab.md>), [home-server](<https://devfeed.tech/tags/home-server.md>), [network](<https://devfeed.tech/tags/network.md>), [proxmox](<https://devfeed.tech/tags/proxmox.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [server](<https://devfeed.tech/tags/server.md>)

### AI overview

The article presents seven reliability tests for home lab services, including disconnecting Internet access and stopping one container in a redundant setup. It explains how these tests can reveal dependencies on external resources and weaknesses in DNS and service design.

### Source excerpt

When it comes to putting a new service into the home lab that is something I will feel like I can rely on and trust, it has to be able... The post I Don't Trust a Home Lab Service Until It Passes These 7 Tests appeared first on Virtualization Howto.

## Forgejo 16.0.4 and 15.0.8 Fix Critical Repository Template RCE

DevFeed: [Forgejo 16.0.4 and 15.0.8 Fix Critical Repository Template RCE](<https://devfeed.tech/articles/forgejo-16-0-4-and-15-0-8-fix-critical-repository-template-rce-10719.md>)

Original publisher: [Read original article](<https://selfhostlab.io/forgejo-16-0-4-security-release/>)

Author: Christian Rakoot

Published: 2026-09-12T06:40:18Z

Content type: article

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [releases](<https://devfeed.tech/topics/releases.md>), [Security](<https://devfeed.tech/topics/security.md>), [Template](<https://devfeed.tech/topics/template.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [API](<https://devfeed.tech/topics/api.md>), [Git](<https://devfeed.tech/topics/git.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [docker-containers](<https://devfeed.tech/tags/docker-containers.md>), [docker-containers-news](<https://devfeed.tech/tags/docker-containers-news.md>), [forgejo](<https://devfeed.tech/tags/forgejo.md>), [git](<https://devfeed.tech/tags/git.md>), [news](<https://devfeed.tech/tags/news.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Forgejo 16.0.4 and 15.0.8 fix a critical remote code execution vulnerability in repository-template creation, along with an API authorization bypass. The article explains how malicious template variables could restore a .git directory with executable hooks and urges affected self-hosted instances to update.

### Source excerpt

Forgejo 16.0.4 and 15.0.8 patch a critical remote code execution vulnerability in repository templates, tracked as CVE-2026-89094 with a CVSS score of 9.9, plus a narrower API permission bypass. Any instance on 16.0.3 or earlier, or 15.0.7 or earlier on the LTS branch, is vulnerable. Here's what happened, why it matters, and how to update.

## I Turned My Proxmox Server Into a NAS Without Installing TrueNAS

DevFeed: [I Turned My Proxmox Server Into a NAS Without Installing TrueNAS](<https://devfeed.tech/articles/i-turned-my-proxmox-server-into-a-nas-without-installing-truenas-10492.md>)

Original publisher: [Read original article](<https://www.virtualizationhowto.com/2026/09/i-turned-my-proxmox-server-into-a-nas-without-installing-truenas/>)

Author: Brandon Lee

Published: 2026-09-10T12:46:18Z

Content type: article

Language: en

Sources: [Virtualization Howto](<https://devfeed.tech/sources/virtualization-howto.md>)

Topics: [Proxmox](<https://devfeed.tech/topics/proxmox.md>), [Homelab](<https://devfeed.tech/topics/homelab.md>), [virtualization](<https://devfeed.tech/topics/virtualization.md>), [hosting](<https://devfeed.tech/topics/hosting.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Debian](<https://devfeed.tech/topics/debian.md>)

Tags: [ceph](<https://devfeed.tech/tags/ceph.md>), [debian](<https://devfeed.tech/tags/debian.md>), [home-lab](<https://devfeed.tech/tags/home-lab.md>), [home-server](<https://devfeed.tech/tags/home-server.md>), [hosting](<https://devfeed.tech/tags/hosting.md>), [linux](<https://devfeed.tech/tags/linux.md>), [nas](<https://devfeed.tech/tags/nas.md>), [proxmox](<https://devfeed.tech/tags/proxmox.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [self-hosting](<https://devfeed.tech/tags/self-hosting.md>), [server](<https://devfeed.tech/tags/server.md>), [storage](<https://devfeed.tech/tags/storage.md>), [virtualization](<https://devfeed.tech/tags/virtualization.md>)

### AI overview

The article presents ANAS, a project that adds native storage-management panels to the existing Proxmox VE web interface. It aims to let Proxmox manage storage using the underlying Debian/Linux capabilities without installing TrueNAS or introducing a separate management interface.

### Source excerpt

Proxmox is really good with all types of storage and I have used it as a dedicated NAS appliance many times. I have used dedicated NAS devices. I have also... The post I Turned My Proxmox Server Into a NAS Without Installing TrueNAS appeared first on Virtualization Howto.

## Building resilient self hosted services is not always easy

DevFeed: [Building resilient self hosted services is not always easy](<https://devfeed.tech/articles/building-resilient-self-hosted-services-is-not-always-easy-10863.md>)

Original publisher: [Read original article](<https://blog.apnic.net/2026/09/09/building-resilient-self-hosted-services-is-not-always-easy/>)

Author: George Michaelson

Published: 2026-09-09T05:10:54Z

Content type: opinion

Language: en

Sources: [APNIC Blog](<https://devfeed.tech/sources/apnic-blog.md>)

Topics: [Pi-hole](<https://devfeed.tech/topics/pihole.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Network Configuration](<https://devfeed.tech/topics/network-configuration.md>), [systems](<https://devfeed.tech/topics/systems.md>), [Server](<https://devfeed.tech/topics/server.md>)

Tags: [dns](<https://devfeed.tech/tags/dns.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [network](<https://devfeed.tech/tags/network.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [router](<https://devfeed.tech/tags/router.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [server](<https://devfeed.tech/tags/server.md>), [systems](<https://devfeed.tech/tags/systems.md>), [tech-matters](<https://devfeed.tech/tags/tech-matters.md>)

### AI overview

The article reflects on the difficulties of running resilient self-hosted DNS services at home. It describes how reboots and router or DNS configuration changes can disrupt DHCP and the wider home network, arguing for independently configured redundant instances and a tested backup plan.

### Source excerpt

Resiliency through more redundancy is important no matter the scenario.

## IBM Research and Red Hat benchmark llm-d serving GLM-5.2 on H100 GPUs

DevFeed: [IBM Research and Red Hat benchmark llm-d serving GLM-5.2 on H100 GPUs](<https://devfeed.tech/articles/how-llm-d-makes-the-most-of-the-hardware-you-already-have-17349.md>)

Original publisher: [Read original article](<https://research.ibm.com/blog/running-open-models-on-h100-gpus-with-llmd>)

Author: Peter Hess

Published: 2026-09-08T12:00:00Z

Content type: article

Language: en

Sources: [IBM Research](<https://devfeed.tech/sources/ibm-research.md>)

Topics: [Inference](<https://devfeed.tech/topics/inference.md>), [GPU](<https://devfeed.tech/topics/gpu.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [ibm](<https://devfeed.tech/topics/ibm.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-for-code](<https://devfeed.tech/tags/ai-for-code.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [gpu](<https://devfeed.tech/tags/gpu.md>), [hybrid-cloud](<https://devfeed.tech/tags/hybrid-cloud.md>), [hybrid-cloud-platform](<https://devfeed.tech/tags/hybrid-cloud-platform.md>), [ibm](<https://devfeed.tech/tags/ibm.md>), [inference](<https://devfeed.tech/tags/inference.md>), [llm](<https://devfeed.tech/tags/llm.md>), [news](<https://devfeed.tech/tags/news.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [scaling-ai](<https://devfeed.tech/tags/scaling-ai.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>)

### AI overview

IBM Research, Red Hat, and collaborators report a benchmark deployment of the llm-d open-source inference framework serving the open-weight GLM-5.2 model on 544 NVIDIA H100 GPUs. The reported workload reached more than 6.6 million output tokens per minute and up to 3,000 concurrent coding agents without preemptions.

### Source excerpt

IBM Research and Red Hat deployed a 753B open model on H100 GPUs, serving thousands of concurrent coding agents at 5-10x lower cost than commercial APIs.

## Introducing worker topologies for self-hosted Appwrite

DevFeed: [Introducing worker topologies for self-hosted Appwrite](<https://devfeed.tech/articles/introducing-worker-topologies-for-self-hosted-appwrite-16446.md>)

Original publisher: [Read original article](<https://appwrite.io/blog/post/announcing-worker-topologies>)

Author: Atharva Deosthale

Published: 2026-09-07T00:00:00Z

Content type: release

Language: en

Sources: [Appwrite Blog](<https://devfeed.tech/sources/appwrite-blog.md>)

Topics: [Appwrite](<https://devfeed.tech/topics/appwrite.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Coroutines](<https://devfeed.tech/topics/coroutines.md>), [Docker Compose](<https://devfeed.tech/topics/docker-compose.md>)

Tags: [announcements](<https://devfeed.tech/tags/announcements.md>), [compose](<https://devfeed.tech/tags/compose.md>), [container](<https://devfeed.tech/tags/container.md>), [containers](<https://devfeed.tech/tags/containers.md>), [coroutines](<https://devfeed.tech/tags/coroutines.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>)

### AI overview

Appwrite introduces two worker topologies for self-hosted instances. The combined topology is now the default and runs background work in two containers, while the separate topology preserves one container per queue and scheduler for installations needing independent scaling or resource controls.

### Source excerpt

Self-hosted Appwrite now runs all background workers in a single container by default. Learn how the combined topology works and when to scale out with separate workers.

## Introducing Postgres to self-hosted Appwrite

DevFeed: [Introducing Postgres to self-hosted Appwrite](<https://devfeed.tech/articles/introducing-postgres-to-self-hosted-appwrite-16448.md>)

Original publisher: [Read original article](<https://appwrite.io/blog/post/appwrite-2-0-postgres-by-default>)

Author: Atharva Deosthale

Published: 2026-09-07T00:00:00Z

Content type: release

Language: en

Sources: [Appwrite Blog](<https://devfeed.tech/sources/appwrite-blog.md>)

Topics: [Appwrite](<https://devfeed.tech/topics/appwrite.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [Docker](<https://devfeed.tech/topics/docker.md>)

Tags: [database](<https://devfeed.tech/tags/database.md>), [docker](<https://devfeed.tech/tags/docker.md>), [install](<https://devfeed.tech/tags/install.md>), [mongodb](<https://devfeed.tech/tags/mongodb.md>), [postgres](<https://devfeed.tech/tags/postgres.md>), [products](<https://devfeed.tech/tags/products.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>)

### AI overview

Appwrite 2.0 makes Postgres the default database for new self-hosted installations. The setup wizard also lets users choose MariaDB or MongoDB. Existing installations keep their current database, and migration to another database is not supported.

### Source excerpt

Appwrite 2.0 runs new self-hosted instances on Postgres by default. Choose Postgres, MariaDB, or MongoDB in the setup wizard when you install.

## n8n Patches 18 Security Vulnerabilities in Bi-Weekly Update

DevFeed: [n8n Patches 18 Security Vulnerabilities in Bi-Weekly Update](<https://devfeed.tech/articles/n8n-patches-18-security-vulnerabilities-in-bi-weekly-update-10724.md>)

Original publisher: [Read original article](<https://selfhostlab.io/n8n-september-2026-security-update/>)

Author: Christian Rakoot

Published: 2026-09-06T06:31:02Z

Content type: article

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [workflow automation](<https://devfeed.tech/topics/workflow-automation.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Code](<https://devfeed.tech/topics/code.md>), [Homelab](<https://devfeed.tech/topics/homelab.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [Regular expression](<https://devfeed.tech/topics/regular-expression.md>), [data](<https://devfeed.tech/topics/data.md>), [Git](<https://devfeed.tech/topics/git.md>), [JSON](<https://devfeed.tech/topics/json.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>)

Tags: [article](<https://devfeed.tech/tags/article.md>), [automation](<https://devfeed.tech/tags/automation.md>), [code](<https://devfeed.tech/tags/code.md>), [data](<https://devfeed.tech/tags/data.md>), [external](<https://devfeed.tech/tags/external.md>), [git](<https://devfeed.tech/tags/git.md>), [json](<https://devfeed.tech/tags/json.md>), [n8n](<https://devfeed.tech/tags/n8n.md>), [n8n-patches-18](<https://devfeed.tech/tags/n8n-patches-18.md>), [news](<https://devfeed.tech/tags/news.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [openai](<https://devfeed.tech/tags/openai.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [workflow](<https://devfeed.tech/tags/workflow.md>), [workflow-automation](<https://devfeed.tech/tags/workflow-automation.md>)

### AI overview

n8n's September 2, 2026 bi-weekly security update fixes 18 vulnerabilities: five high-severity and thirteen medium-severity issues. The most serious flaws are two expression-sandbox escapes that can enable arbitrary code execution on self-hosted servers. Other high-severity fixes address denial-of-service, ReDoS, and an OpenAI model-search domain-restriction bypass.

### Source excerpt

Read this article in French: n8n corrige 18 failles de sécurité dans sa mise à jour bi-hebdomadaire n8n is one of the most widely deployed self-hosted workflow automation platforms, often described as the fair-code alternative to Zapier and Make. People use it to move data between apps, trigger scripts on a schedule, and glue together [...]

## Self-Hosted Platform Build Order: Dependencies from Bare Metal to Model Serving

DevFeed: [Self-Hosted Platform Build Order: Dependencies from Bare Metal to Model Serving](<https://devfeed.tech/articles/the-whole-estate-in-one-article-how-every-layer-fits-together-34108.md>)

Original publisher: [Read original article](<https://philipptheserver.com/posts/meta-infrastructure-overview/>)

Author: Philipp Lehmann (philipp.lehmann@gruppe.ai)

Published: 2026-09-04T07:00:00Z

Content type: article

Language: en

Sources: [Philipp Lehmann](<https://devfeed.tech/sources/philipp-lehmann.md>)

Topics: [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>), [Ansible](<https://devfeed.tech/topics/ansible.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [ceph](<https://devfeed.tech/topics/ceph.md>), [observability](<https://devfeed.tech/topics/observability.md>), [model-serving](<https://devfeed.tech/topics/model-serving.md>), [Compose](<https://devfeed.tech/topics/compose.md>)

Tags: [ansible](<https://devfeed.tech/tags/ansible.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [article](<https://devfeed.tech/tags/article.md>), [ceph](<https://devfeed.tech/tags/ceph.md>), [compose](<https://devfeed.tech/tags/compose.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [model-serving](<https://devfeed.tech/tags/model-serving.md>), [observability](<https://devfeed.tech/tags/observability.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>)

### AI overview

This article explains the dependency order for building a self-hosted platform. It covers consistent bare-metal inventory, Ansible configuration convergence, networking, Kubernetes, Ceph storage, identity, observability, and model serving.

### Source excerpt

Self-hosted platform build order: why mesh, cluster, Ceph storage, identity and observability must precede model serving, shown with Compose depends_on.

## Pi-hole vs AdGuard Home vs Technitium: which DNS ad-blocker to run

DevFeed: [Pi-hole vs AdGuard Home vs Technitium: which DNS ad-blocker to run](<https://devfeed.tech/articles/pi-hole-vs-adguard-home-vs-technitium-which-dns-ad-blocker-to-run-10749.md>)

Original publisher: [Read original article](<https://shedstack.dev/posts/pi-hole-vs-adguard-home-vs-technitium.html>)

Author: Shed Stack

Published: 2026-09-02T18:00:00Z

Content type: comparison

Language: en

Sources: [Shed Stack](<https://devfeed.tech/sources/shed-stack.md>)

Topics: [Pi-hole](<https://devfeed.tech/topics/pihole.md>), [Homelab](<https://devfeed.tech/topics/homelab.md>), [DNSSEC](<https://devfeed.tech/topics/dnssec.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>)

Tags: [ads](<https://devfeed.tech/tags/ads.md>), [comparison](<https://devfeed.tech/tags/comparison.md>), [dns](<https://devfeed.tech/tags/dns.md>), [dnssec](<https://devfeed.tech/tags/dnssec.md>), [features](<https://devfeed.tech/tags/features.md>), [go](<https://devfeed.tech/tags/go.md>), [homelab](<https://devfeed.tech/tags/homelab.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>)

### AI overview

Practical comparison of Pi-hole, AdGuard Home, and Technitium as self-hosted DNS ad-blockers. Pi-hole emphasizes its mature blocklist ecosystem, AdGuard Home offers a broader built-in feature set and modern interface, and Technitium provides a full DNS server with blocking capabilities for users who want greater control over DNS.

### Source excerpt

A practical breakdown of the three self-hosted DNS ad-blockers, from a homelab that actually ran all of them.

## Paperless-ngx 3.1.0 Adds AI Workflow Actions and Document Versioning

DevFeed: [Paperless-ngx 3.1.0 Adds AI Workflow Actions and Document Versioning](<https://devfeed.tech/articles/paperless-ngx-3-1-0-adds-ai-workflow-actions-and-document-versioning-10726.md>)

Original publisher: [Read original article](<https://selfhostlab.io/paperless-ngx-3-1-0-ai-workflow-versioning/>)

Author: Christian Rakoot

Published: 2026-08-31T06:39:07Z

Content type: news

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [Compression](<https://devfeed.tech/topics/compression.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [bug](<https://devfeed.tech/tags/bug.md>), [changelog](<https://devfeed.tech/tags/changelog.md>), [compression](<https://devfeed.tech/tags/compression.md>), [identity](<https://devfeed.tech/tags/identity.md>), [news](<https://devfeed.tech/tags/news.md>), [news-personal-cloud](<https://devfeed.tech/tags/news-personal-cloud.md>), [ocr](<https://devfeed.tech/tags/ocr.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [paperless-ngx](<https://devfeed.tech/tags/paperless-ngx.md>), [personal-cloud](<https://devfeed.tech/tags/personal-cloud.md>), [release](<https://devfeed.tech/tags/release.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [updates](<https://devfeed.tech/tags/updates.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

Paperless-ngx 3.1.0 adds automatic AI-based workflow classification, per-document remote OCR selection, OIDC group synchronization, document versioning, configurable ZIP compression, and smaller fixes.

### Source excerpt

Paperless-ngx 3.1.0 landed on August 27, 2026, adding a workflow action that applies AI-generated tag and correspondent suggestions automatically, per-document selective remote OCR, OIDC group sync mapping identity-provider groups to superuser and staff roles, a new versioning system for merging documents into successive versions, configurable ZIP export compression, and numerous smaller UI bug fixes sitewide.

## BookStack Security Update Patches Critical RCE Flaw in v26.05.4

DevFeed: [BookStack Security Update Patches Critical RCE Flaw in v26.05.4](<https://devfeed.tech/articles/bookstack-security-update-patches-critical-rce-flaw-in-v26-05-4-10718.md>)

Original publisher: [Read original article](<https://selfhostlab.io/bookstack-security-update-26-05-4/>)

Author: Christian Rakoot

Published: 2026-08-31T06:36:25Z

Content type: news

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [bookstack-security](<https://devfeed.tech/tags/bookstack-security.md>), [news](<https://devfeed.tech/tags/news.md>), [news-personal-cloud](<https://devfeed.tech/tags/news-personal-cloud.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [personal-cloud](<https://devfeed.tech/tags/personal-cloud.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

BookStack v26.05.4 is a dedicated security release that fixes four vulnerabilities, including a critical authenticated remote code execution flaw involving crafted ZIP imports, an XSS issue, and two draft-page permission bypasses. The article recommends updating and restricting import permissions if an immediate update is not possible.

### Source excerpt

BookStack v26.05.4, released August 24, 2026, is a dedicated security update patching four vulnerabilities: a critical RCE (CVE-2026-82450) exploitable through crafted ZIP imports, an XSS flaw in drawing endpoints, and two permission bypasses affecting draft pages. The BookStack team recommends updating everyone, but especially instances where untrusted users hold general or edit-level access to content.

## Open WebUI v0.11.1 Adds Human-in-the-Loop Tool Approval

DevFeed: [Open WebUI v0.11.1 Adds Human-in-the-Loop Tool Approval](<https://devfeed.tech/articles/open-webui-v0-11-1-adds-human-in-the-loop-tool-approval-10725.md>)

Original publisher: [Read original article](<https://selfhostlab.io/open-webui-v0-11-1-human-in-the-loop/>)

Author: Christian Rakoot

Published: 2026-08-30T06:34:36Z

Content type: article

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Terminal](<https://devfeed.tech/topics/terminal.md>), [Homelab](<https://devfeed.tech/topics/homelab.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [bugs](<https://devfeed.tech/tags/bugs.md>), [homelab](<https://devfeed.tech/tags/homelab.md>), [news](<https://devfeed.tech/tags/news.md>), [news-self-hosted-ai](<https://devfeed.tech/tags/news-self-hosted-ai.md>), [open-webui](<https://devfeed.tech/tags/open-webui.md>), [release](<https://devfeed.tech/tags/release.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [self-hosted-ai](<https://devfeed.tech/tags/self-hosted-ai.md>)

### AI overview

Open WebUI v0.11.1 adds human-in-the-loop approval for selected AI tool calls, allowing users to review actions before execution. The release also fixes terminal-attached chat failures and two calendar timezone-related bugs.

### Source excerpt

Open WebUI v0.11.1 adds human-in-the-loop tool approval, letting you manually confirm certain tool calls before the AI runs them. The release also fixes chats with an attached personal terminal, plus two calendar bugs: new events now default to today's date, and recurring events finally display at the time you actually configured, not a miscalculated one.

## Gitea RCE Flaw Now Under Active Exploitation, CISA Confirms

DevFeed: [Gitea RCE Flaw Now Under Active Exploitation, CISA Confirms](<https://devfeed.tech/articles/gitea-rce-flaw-now-under-active-exploitation-cisa-confirms-10721.md>)

Original publisher: [Read original article](<https://selfhostlab.io/gitea-rce-active-exploitation/>)

Author: Christian Rakoot

Published: 2026-08-29T06:33:49Z

Content type: news

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [Gitea](<https://devfeed.tech/topics/gitea.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [Docker Container](<https://devfeed.tech/topics/docker-container.md>)

Tags: [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [docker-container](<https://devfeed.tech/tags/docker-container.md>), [gitea-rce](<https://devfeed.tech/tags/gitea-rce.md>), [hosting](<https://devfeed.tech/tags/hosting.md>), [incident](<https://devfeed.tech/tags/incident.md>), [network-security](<https://devfeed.tech/tags/network-security.md>), [network-security-news](<https://devfeed.tech/tags/network-security-news.md>), [news](<https://devfeed.tech/tags/news.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

CISA confirmed that the critical Gitea vulnerability CVE-2026-60004 is being actively exploited and added it to the Known Exploited Vulnerabilities catalog. The article explains the exploit through Gitea's diffpatch API, which can enable arbitrary code execution, and describes a documented compromise of an outdated self-hosted instance that led to cryptocurrency mining inside a Docker container.

### Source excerpt

CISA has added CVE-2026-60004, the critical Gitea RCE flaw patched in version 1.27.1, to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Help Net Security documented a real compromise: an outdated instance with open registration hit by an automated scanner, ending in a cryptocurrency-mining payload. Here is what changed and how to patch.

## IPFS is moving beyond the sponsored gateways

DevFeed: [IPFS is moving beyond the sponsored gateways](<https://devfeed.tech/articles/ipfs-is-moving-beyond-the-sponsored-gateways-35631.md>)

Original publisher: [Read original article](<https://blog.ipfs.tech/2026-08-beyond-sponsored-gateways/>)

Published: 2026-08-25T00:00:00Z

Content type: release

Language: en

Sources: [IPFS](<https://devfeed.tech/sources/ipfs.md>)

Topics: [IPFS](<https://devfeed.tech/topics/ipfs.md>), [gateway](<https://devfeed.tech/topics/gateway.md>), [P2P](<https://devfeed.tech/topics/p2p.md>), [browser](<https://devfeed.tech/topics/browser.md>)

Tags: [distributed](<https://devfeed.tech/tags/distributed.md>), [gateway](<https://devfeed.tech/tags/gateway.md>), [ipfs](<https://devfeed.tech/tags/ipfs.md>), [object-object](<https://devfeed.tech/tags/object-object.md>), [open-web](<https://devfeed.tech/tags/open-web.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [time](<https://devfeed.tech/tags/time.md>)

### AI overview

IPFS is changing how the ipfs.io and dweb.link gateways operate, shifting content retrieval from centralized servers toward service workers that connect directly to peers and verify content in the browser. The article also describes self-hosted gateways, browser-based IPFS nodes, and paid pinning and retrieval providers as alternatives.

### Source excerpt

How IPFS is shifting from centralized public gateways to distributed infrastructure and client-side retrieval.

## Preloading Knowledge Into a Model Instead of Retrieving It

DevFeed: [Preloading Knowledge Into a Model Instead of Retrieving It](<https://devfeed.tech/articles/preloading-knowledge-into-a-model-instead-of-retrieving-it-18241.md>)

Original publisher: [Read original article](<https://blog.dailydoseofds.com/p/preloading-knowledge-into-a-model>)

Author: Avi Chawla

Published: 2026-08-24T17:13:39Z

Content type: tutorial

Language: en

Sources: [Daily Dose of Data Science](<https://devfeed.tech/sources/daily-dose-of-data-science.md>)

Topics: [Retrieval Augmented Generation (RAG)](<https://devfeed.tech/topics/retrieval-augmented-generation-rag.md>), [Caching](<https://devfeed.tech/topics/caching.md>), [long-context](<https://devfeed.tech/topics/long-context.md>), [Inference](<https://devfeed.tech/topics/inference.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>), [model-deployment](<https://devfeed.tech/topics/model-deployment.md>), [GPU](<https://devfeed.tech/topics/gpu.md>)

Tags: [caching](<https://devfeed.tech/tags/caching.md>), [compute](<https://devfeed.tech/tags/compute.md>), [context-window](<https://devfeed.tech/tags/context-window.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [inference](<https://devfeed.tech/tags/inference.md>), [rag](<https://devfeed.tech/tags/rag.md>), [retrieval](<https://devfeed.tech/tags/retrieval.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [storage](<https://devfeed.tech/tags/storage.md>)

### AI overview

This article introduces a three-part RAG Systems course about preloading a knowledge corpus into a model's stored KV cache so subsequent queries can skip retrieval, chunking, and embedding. It covers naive, compressed, modular, and trained preloading, along with context limits, provider and self-hosted economics, cache compression constraints, and production deployment.

### Source excerpt

How to process your corpus once, skip retrieval entirely, and serve every query from a stored cache. Three parts covering the full spectrum.

## How Razorpay Cut Its Metrics Bill by 62% Without Losing a Dashboard

DevFeed: [How Razorpay Cut Its Metrics Bill by 62% Without Losing a Dashboard](<https://devfeed.tech/articles/how-razorpay-cut-its-metrics-bill-by-62-without-losing-a-dashboard-24039.md>)

Original publisher: [Read original article](<https://engineering.razorpay.com/how-razorpay-cut-its-metrics-bill-by-62-without-losing-a-dashboard-2a7d5467df37?source=rss----6407ad2e59af---4>)

Author: Dhairya Mehta

Published: 2026-08-24T10:25:21Z

Content type: article

Language: en

Sources: [Razorpay Engineering - Medium](<https://devfeed.tech/sources/razorpay-engineering-medium.md>)

Topics: [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [migration](<https://devfeed.tech/topics/migration.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>)

Tags: [cost](<https://devfeed.tech/tags/cost.md>), [high-availability](<https://devfeed.tech/tags/high-availability.md>), [incident](<https://devfeed.tech/tags/incident.md>), [metrics](<https://devfeed.tech/tags/metrics.md>), [migration](<https://devfeed.tech/tags/migration.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>)

### AI overview

Razorpay reduced daily metrics ingestion from about 450 billion to about 170 billion samples, cutting its metrics bill by 62% without deleting useful dashboards or breaking alerts. The article describes an audit conducted during a planned migration from a self-hosted VictoriaMetrics cluster to a managed monitoring platform, covering scrape intervals, duplicate high-availability scrapes, and high-cardinality metrics.

### Source excerpt

Contributor: Saijal Shrivastava We cut our metrics ingestion by 62% without deleting a single useful dashboard or breaking an alert. Daily ingestion dropped from about 450 billion samples to about 170 billion. The surprising part was not one large optimization. It was three simple discoveries hiding in plain sight: Scrape intervals can multiply ingestion. High-availability scraping can silently send duplicate metrics when deduplication happens only at the storage layer. High-cardinality metrics are easy to create, expensive to keep, and hard to remove without ownership. We found these while preparing to move from a self-hosted VictoriaMetrics cluster to a managed monitoring platform. The migration started as a reliability project. The audit turned it into a cost and signal-quality project. We were not just moving monitoring data. We were moving years of accumulated assumptions about what was worth scraping. The Incident that Forced the Audit Our self-hosted VictoriaMetrics cluster had served us well for years. Then one storage node hit EBS volume throttling. Traffic shifted to the remaining storage nodes, the extra load pushed another node past its limits, and the storage layer collapsed. We saw the same pattern whenever a storage node became unavailable: traffic redistributed, the remaining nodes overloaded, and the cluster moved back toward failure. The collection, ingestion, and query components were still running, so the system looked alive from the outside. But the storage layer was down. Metrics stopped being persisted. Dashboards went blank. Alerts stopped evaluating. Recovery took hours. Teams fell back to logs and manual checks to understand production health. Figure 1: Cascading failure in the pipeline That made the reliability problem obvious. We needed a more stable monitoring architecture. We evaluated several options: self-hosted designs with disaster recovery built in, and fully managed alternatives. But when we priced the managed options, one number

## Agentic Search. More accurate and efficient results from your AI systems.

DevFeed: [Agentic Search. More accurate and efficient results from your AI systems.](<https://devfeed.tech/articles/agentic-search-more-accurate-and-efficient-results-from-your-ai-systems-6968.md>)

Original publisher: [Read original article](<https://mistral.ai/news/agentic-search/>)

Published: 2026-08-20T12:00:17Z

Content type: release

Language: en

Sources: [Mistral AI Blog](<https://devfeed.tech/sources/mistral-ai-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [data](<https://devfeed.tech/topics/data.md>), [Benchmark](<https://devfeed.tech/topics/benchmark.md>), [Latency](<https://devfeed.tech/topics/latency.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [benchmark](<https://devfeed.tech/tags/benchmark.md>), [benchmarks](<https://devfeed.tech/tags/benchmarks.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [data](<https://devfeed.tech/tags/data.md>), [latency](<https://devfeed.tech/tags/latency.md>), [open](<https://devfeed.tech/tags/open.md>), [portable](<https://devfeed.tech/tags/portable.md>), [retrieval](<https://devfeed.tech/tags/retrieval.md>), [search](<https://devfeed.tech/tags/search.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>)

### AI overview

Mistral Agentic Search is a retrieval layer for AI systems that uses a multi-step loop to find, inspect, and verify information across complex documents and data sources. The article reports higher accuracy on FinanceBench and OfficeQA Pro, along with reductions in latency and token use. It is available through the Mistral Search Toolkit and Libraries, with support for existing indexes and sensitive data in cloud and on-premises environments.

### Source excerpt

The retrieval layer that helps AI systems navigate, read, and verify information inside even the most complex documents

## LibreDB Studio: an open source, self-hosted SQL IDE for PostgreSQL in the browser

DevFeed: [LibreDB Studio: an open source, self-hosted SQL IDE for PostgreSQL in the browser](<https://devfeed.tech/articles/libredb-studio-an-open-source-self-hosted-sql-ide-for-postgresql-in-the-browser-4716.md>)

Original publisher: [Read original article](<https://www.postgresql.org/about/news/libredb-studio-an-open-source-self-hosted-sql-ide-for-postgresql-in-the-browser-3368/>)

Published: 2026-08-20T00:00:00Z

Content type: article

Language: en

Sources: [PostgreSQL news](<https://devfeed.tech/sources/postgresql-news.md>)

Topics: [PostgreSQL](<https://devfeed.tech/topics/postgresql.md>), [ide](<https://devfeed.tech/topics/ide.md>), [SQL](<https://devfeed.tech/topics/sql.md>), [browser](<https://devfeed.tech/topics/browser.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [API](<https://devfeed.tech/topics/api.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Back end](<https://devfeed.tech/topics/backend.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [backend](<https://devfeed.tech/tags/backend.md>), [browser](<https://devfeed.tech/tags/browser.md>), [ide](<https://devfeed.tech/tags/ide.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [postgresql](<https://devfeed.tech/tags/postgresql.md>), [release](<https://devfeed.tech/tags/release.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [sql](<https://devfeed.tech/tags/sql.md>)

### AI overview

LibreDB Studio is an MIT-licensed, self-hosted SQL IDE for PostgreSQL that runs in the browser and can be deployed as a container, Helm chart, or npm package. The article describes its database-aware query editing, transaction controls, schema introspection, monitoring, optional query assistant, and local-account or OIDC authentication with role-based access control. Release 0.12.0 is highlighted.

### Source excerpt

LibreDB Studio is an MIT-licensed, self-hosted SQL IDE for PostgreSQL that runs in the browser and deploys as a container or Helm chart. It is deployed next to the database it manages, as a container, a Helm chart or an npm package, rather than installed on each developer's machine. PostgreSQL is its reference implementation: the provider is built on node-postgres, and the other supported engines follow the patterns established there. On a PostgreSQL connection the editor uses pooled connections, explicit BEGIN/COMMIT/ROLLBACK transactions with an auto-rollback timeout, and query cancellation through pg_cancel_backend on the tracked backend PID. Schema introspection is written to stay responsive on databases with hundreds of tables: the table tree renders from a first pass while relationships stream in from a second. Monitoring reads the pg_stat_* views, including pg_stat_statements where the extension is installed, and degrades to what the connected role can actually see instead of failing when superuser-only views are unavailable. The optional query assistant is constrained by the database rather than by prompt text. A run is given the real schema of the connected database before its first turn, so a drafted statement names objects that exist, and read-only runs execute inside BEGIN READ ONLY as a single statement over the extended protocol. Authentication is local accounts or OIDC, with role-based access control in front of every API route. The current release is 0.12.0. Source, documentation and the PostgreSQL provider reference are at github.com/libredb/libredb-studio and libredb.org.

[Next page](<https://devfeed.tech/tags/self-hosted.md?cursor=WyIyMDI2LTA4LTIwVDAwOjAwOjAwKzAwOjAwIiwgIjBjMTJiN2I0LTM2ZGEtNGExZS05ZTU5LTVjNjJmZmMxMjNhNCJd>)